What is STACKIT Confidential Kubernetes?
STACKIT Confidential Kubernetes is a confidential computing platform that allows containerized applications to run in a cluster shielded from the underlying cloud infrastructure. All Kubernetes nodes run as Confidential Virtual Machines (CVMs) with hardware-based memory encryption (runtime encryption). This keeps data protected even while it is being processed in memory and allows its integrity to be cryptographically verified.
Core Features
- Hardware-isolated cluster nodes based on Confidential Virtual Machines
- Transparent encryption of network and storage
- Remote attestation for individual nodes joining the cluster
- Proof of integrity for the entire cluster via a hardware-bound certificate
- Automated, transparent key management within the isolated environment
Typical Use Cases
Regulated industries: Healthcare, finance, and the public sector with strict data protection and auditability requirements.
Cloud migration of sensitive workloads: Organizations moving on-premises workloads with private-cloud-level security requirements into the public cloud.
Trustworthy SaaS offerings: Providers who want to cryptographically prove the isolation and integrity of their platform to customers.
Benefits
- Closes the gap between encryption at rest/in transit and encryption during processing
- Operated in German STACKIT data centers, GDPR compliant
- Verifiable security through remote attestation rather than pure trust in the provider
- Enterprise-ready DevOps features (high availability, upgrades, infrastructure-as-code support)
Integration with innFactory
As an official STACKIT partner, innFactory supports the introduction of Confidential Kubernetes: from architecture and migration of existing workloads to ongoing operations and cost optimization.
Available Tiers & Options
Confidential
- Hardware-based isolation of cluster nodes
- Remote attestation for individual nodes and the whole cluster
- Encryption of storage and network
- Currently provided on a customer-specific basis, not full self-service
- Additional operational overhead compared to standard SKE
Typical Use Cases
Frequently Asked Questions
What is STACKIT Confidential Kubernetes?
A confidential computing platform that lets customers run containerized applications in a cluster shielded from the underlying cloud infrastructure at the hardware level. All Kubernetes nodes run as Confidential Virtual Machines (CVMs).
How does the encryption work?
All Kubernetes nodes run inside encrypted CVMs. Network and storage are encrypted transparently, protecting data at rest, in transit, and while being processed in memory.
What does STACKIT Confidential Kubernetes cost?
The service is currently offered on a customer-specific basis; a concrete quote is obtained through STACKIT sales. Since 1 December 2025, STACKIT bills compute resources and the associated license as separate SKUs instead of a single combined product.
How can I verify the integrity of my cluster?
Each new node is verified via remote attestation before it is granted access to the cluster. The integrity of the entire cluster can additionally be proven using a hardware-bound certificate.
Where can I find the official documentation?
STACKIT currently does not publish public technical documentation for Confidential Kubernetes in its docs portal; the former "Confidential Computing" category is no longer available there. The official product page is the authoritative source, and technical details are available via STACKIT sales.
What use cases fit Confidential Kubernetes?
Regulated industries with strict compliance requirements, migrating sensitive workloads to the cloud, and providers who want to increase the trustworthiness of their SaaS offering through verifiable isolation.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.
